If you are using the distributed solution and multitenancy mode, use the web interface of the PCN or SCN server for which you want to configure parameters.
Operation mode in which Kaspersky Anti Targeted Attack Platform is used to protect the infrastructure of multiple organizations or branch offices of the same organization simultaneously.
Two-level hierarchy of servers with Central Node components installed. This hierarchy allocates a primary control server (Primary Central Node (PCN)) and secondary servers (Secondary Central Nodes (SCN)).
The table of user-defined TAA (IOA) rules contains information about TAA (IOA) rules that are used to scan events and create alerts; the table is in the Custom rules section, TAA subsection of the program web interface window.
The table contains the following information:
—Importance level that is assigned to an alert generated using this TAA (IOA) rule.
The importance level can have one of the following values:
– Low.
– Medium.
– High.
Type is the type of the rule depending on the operating mode of the program and the role of the server which generated the rule:
Global—Created on the PCN server. These rules are used to scan events on this PCN server and all SCN servers connected to this PCN server. Scanned events belong to the tenant which the user is managing in the program web interface.
Local—Created on the SCN server. These rules are used to scan events on this SCN server. Scanned events belong to the tenant which the user is managing in the program web interface.
Confidence is the level of confidence depending on the likelihood of false alarms caused by the rule:
High.
Medium.
Low.
The higher the confidence, the lower the likelihood of false alarms.
Name – name of the rule.
Servers – name of the server with the Central Node component on which the rule is applied.
Generate alerts – requirement to store information on alerts based on matching an event from the database with criteria of the rule.
Enabled – a record is created for the event in the alerts table with Targeted Attack Analyzer (TAA) technology specified.